Our Commitment to GDPR
ion-point is committed to complying with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area (EEA) and the United Kingdom.
This page explains how we meet our obligations under GDPR and what rights you have regarding your personal data.
Lawful Basis for Processing
We process personal data under the following lawful bases:
Consent
When you provide explicit consent for us to process your data for specific purposes, such as marketing communications.
Contract Performance
When processing is necessary to fulfill our contractual obligations to you, such as delivering training programs you've enrolled in.
Legitimate Interests
When we have a legitimate interest in processing your data, such as improving our services or preventing fraud, provided this does not override your fundamental rights and freedoms.
Legal Obligation
When processing is necessary to comply with legal obligations, such as tax and accounting requirements.
Your Rights Under GDPR
Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request.
Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restriction of Processing
You have the right to request that we limit how we use your personal data in certain situations.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you. We do not engage in automated decision-making of this nature.
How to Exercise Your Rights
To exercise any of your rights under GDPR, please contact us at:
Email: [email protected]
We will respond to your request within one month. In complex cases, we may extend this period by an additional two months, and we will inform you of any such extension.
Data Protection Officer
For any questions or concerns about how we handle your personal data, you can contact our Data Protection Officer at:
Email: [email protected]
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication mechanisms
- Staff training on data protection and security
- Incident response procedures
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
International Data Transfers
When we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Binding Corporate Rules where applicable
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Our standard retention periods are:
- Program participant data: 7 years after program completion
- Marketing communications data: Until consent is withdrawn
- Website analytics data: 26 months
- Financial records: As required by UK tax law (currently 6 years)
Third-Party Processors
We work with carefully selected third-party processors who handle personal data on our behalf. All processors are contractually required to:
- Process data only according to our instructions
- Implement appropriate security measures
- Assist us in meeting our GDPR obligations
- Delete or return data when the processing is complete
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority.
In the UK, the relevant authority is:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Telephone: 0303 123 1113
Updates to This Page
We may update this GDPR compliance page periodically to reflect changes in our practices or legal requirements. Please check this page regularly for updates.
Last updated: June 2, 2026